Vulnerability Name: | CVE-2004-2632 (CCN-16555) | ||||||||
Assigned: | 2004-06-30 | ||||||||
Published: | 2004-06-30 | ||||||||
Updated: | 2017-07-20 | ||||||||
Summary: | phpMyAdmin 2.5.1 up to 2.5.7 allows remote attackers to modify configuration settings and gain unauthorized access to MySQL servers via modified $cfg['Servers'] variables. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | File Manipulation | ||||||||
References: | Source: BUGTRAQ Type: Exploit 20040628 php codes injection in phpMyAdmin version 2.5.7. Source: BUGTRAQ Type: UNKNOWN 20040630 Re: php codes injection in phpMyAdmin version 2.5.7. Source: MITRE Type: CNA CVE-2004-2632 Source: MISC Type: Exploit http://eagle.kecapi.com/sec/fd/phpMyAdmin.html Source: CCN Type: SA11974 phpMyAdmin Configuration Manipulation and Code Injection Source: SECUNIA Type: Patch, Vendor Advisory 11974 Source: SECTRACK Type: Exploit 1010614 Source: CCN Type: SECTRACK ID: 1010614 phpMyAdmin Input Validation Errors in `left.php` May Let Remote Users Execute Arbitrary PHP Code Source: CCN Type: GLSA-200407-22 phpMyAdmin: Multiple vulnerabilities Source: GENTOO Type: Patch GLSA-200407-22 Source: OSVDB Type: Patch 7315 Source: CCN Type: OSVDB ID: 7315 phpMyAdmin Arbitrary Database Access Source: CCN Type: phpMyAdmin Web site phpMyAdmin - Mysql DB administration tool Source: CONFIRM Type: Patch http://www.phpmyadmin.net/home_page/security.php?issue=PMASA-2004-1 Source: BID Type: Exploit, Patch 10629 Source: CCN Type: BID-10629 phpMyAdmin Multiple Input Validation Vulnerabilities Source: XF Type: UNKNOWN phpmyadmin-code-manipulation(16555) Source: XF Type: UNKNOWN phpmyadmin-code-manipulation(16555) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |